• WANTED: Happy members who like to discuss audio and other topics related to our interest. Desire to learn and share knowledge of science required. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Intel Kernel Bug

D

Deleted member 65

Guest
Just checked my Dell desktop and the Intel program says it is not vulnerable, has already been patched. I did a BIOS update a few days ago so maybe that was it?

If your Dell has a 22nm CPU as my Dell has it's not on the affected CPU list.
 
D

Deleted member 65

Guest
Intels utility is only telling us half the truth i.e. does not check for CPU firmware update.
See below test I did using different utility recommending me to update my Dell Laptop BIOS whereas Intels utility says laptop is Not vulnerable.

Edit/Update: My conclusion is that regardless of Windows OS patch or not every PC not having the CPU microcode update is vulnerable since the MS OS patch is not enabled without the HW patch. So there we are, Intel's utility is lying to us!

upload_2018-1-10_13-22-21.png
 
Last edited by a moderator:

Sal1950

Grand Contributor
The Chicago Crusher
Forum Donor
Joined
Mar 1, 2016
Messages
14,165
Likes
16,867
Location
Central Fl

amirm

Founder/Admin
Staff Member
CFO (Chief Fun Officer)
Joined
Feb 13, 2016
Messages
44,595
Likes
239,613
Location
Seattle Area
Intels utility is only telling us half the truth i.e. does not check for CPU firmware update.
I think the Intel utility is for something else! I say that because it came out a couple of months ago and the obscure text around what it does, does not refer to latest breaches. Intel did not admit to this problem until very recently so that tool/vulnerability must be for something else.

This is scary because that exposure is also serious yet none of us impacted have fixes for it! Sad that even big computer companies don't take security seriously. They are so spoiled just waiting for Microsoft to do the work for them. Now that it is their turn with hardware problems, they don't have the processes and systems in place to notify impacted people.
 
D

Deleted member 65

Guest
I think the Intel utility is for something else! I say that because it came out a couple of months ago and the obscure text around what it does, does not refer to latest breaches. Intel did not admit to this problem until very recently so that tool/vulnerability must be for something else.

This is scary because that exposure is also serious yet none of us impacted have fixes for it! Sad that even big computer companies don't take security seriously. They are so spoiled just waiting for Microsoft to do the work for them. Now that it is their turn with hardware problems, they don't have the processes and systems in place to notify impacted people.

PowerShell – Check For Meltdown and Spectre

This PS C:\WINDOWS\system32> Get-SpeculationControlSettings Windows 10 utility works unlike Intel's utility.

Instructions here how to get it: https://www.tweakhound.com/2018/01/05/powershell-check-meltdown-spectre/
 

Sal1950

Grand Contributor
The Chicago Crusher
Forum Donor
Joined
Mar 1, 2016
Messages
14,165
Likes
16,867
Location
Central Fl
No, it is an OS (software) driver. It interfaces with a small "secure" processor inside the CPU.
Same answer in Win 10?
Capture.JPG
 

Brad

Active Member
Joined
Nov 8, 2016
Messages
114
Likes
35
Using that power shell script above looks like it would open a whole slew of security holes
 

amirm

Founder/Admin
Staff Member
CFO (Chief Fun Officer)
Joined
Feb 13, 2016
Messages
44,595
Likes
239,613
Location
Seattle Area
Same answer in Win 10?
Ah, I see the problem now. Your CPU is: Processor Name: Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz. That is a much older CPU (Core 2) and doesn't have this security microprocessor in there to report anything. IN other words it is not compatible with your CPU.
 

Sal1950

Grand Contributor
The Chicago Crusher
Forum Donor
Joined
Mar 1, 2016
Messages
14,165
Likes
16,867
Location
Central Fl
Ah, I see the problem now. Your CPU is: Processor Name: Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz. That is a much older CPU (Core 2) and doesn't have this security microprocessor in there to report anything. IN other words it is not compatible with your CPU.
OK thanks, guess I just won't worry about it for now.
This box I built in 2008 is still running fine and power wise is all the computer I need, still lightening fast to me, specially under linux. ;)
 
D

Deleted member 65

Guest
Using that power shell script above looks like it would open a whole slew of security holes

It's not for everyone, authors are Microsoft Security Response Center. They're still on my list of trusted providers ... ;-)
 
D

Deleted member 65

Guest
Man that is one convoluted way to get you to where you want to go! :) Did you get through the install?

Yes, very straightforward installation, see my post #62 above.

(CVE-2017-5715) known as "Spectre". Fixed by MS patch together with CPU firmware update.

(CVE-2017-5754) known as "Meltdown". Fixed by MS patch, does not rely on CPU firmware update.

Below applies to me as well, bought my Intel i7-8700 a couple of months ago.

https://www.tweakhound.com/2018/01/05/dear-intel-corporation/

"Dear Intel Corporation,
You were informed of the flaws in your CPUs months ago. Specifically, Spectre on June 1st, and Meltdown on July 28th of last year.
In December of last year I spent $1,877.34 on a new computer system based on the i7-8700k CPU, a CPU you long knew to have a major security issue. You should have stopped CPU sales as soon as you knew how bad the security issue with your CPUs were.
You knowingly sold me a flawed product and you are responsible for not only that but the related purchases, the time wasted, the sleepless nights and anguish. So, you owe me $1,877.34 + $1000 for time wasted + $5000 for pain and suffering. Complete breakdown is available on request. I expect this to be paid promptly.
Thank you,
"​
 
Last edited by a moderator:
D

Deleted member 65

Guest
Tool to check for Meltdown & Spectre vulnerability (works unlike Intel's biased tool):

https://www.grc.com/inspectre.htm

upload_2018-1-21_12-16-46.png


Performance benchmark after applying Spectre & Meltdown patches on Intel i7-8700K CPU (latest CPU generation):

Results

Intel claimed a 4% overall hit for my CPU in their PCMark 10benchmark tests. (They continue to act like that is acceptable.)
My results:
A loss of 4.9% overall, with a high of 7.9% in Productivity.

Frequent reboots/System crash


The models that may experience this behavior have expanded to Broadwell, Haswell, Ivy Bridge, Sandy Bridge, Skylake, and Kaby Lake. That is basically everything in the last 7 years.

 

amirm

Founder/Admin
Staff Member
CFO (Chief Fun Officer)
Joined
Feb 13, 2016
Messages
44,595
Likes
239,613
Location
Seattle Area
OP
DonH56

DonH56

Master Contributor
Technical Expert
Forum Donor
Joined
Mar 15, 2016
Messages
7,880
Likes
16,666
Location
Monument, CO
My result's the same on my notebook, which figures since there has not been a BIOS update and historically I've had problems getting updates from them (MSI). Have to try on my desktop later. At least it says the only problem is the BIOS; SW/OS is OK.
 

Sal1950

Grand Contributor
The Chicago Crusher
Forum Donor
Joined
Mar 1, 2016
Messages
14,165
Likes
16,867
Location
Central Fl
Tool to check for Meltdown & Spectre vulnerability (works unlike Intel's biased tool):
Excellent. Just click download and run. It runs instantly without installing a bunch of nonsense. My results are sad though:
What gives you the confidence that this piece of software can be trusted in any way?
 

amirm

Founder/Admin
Staff Member
CFO (Chief Fun Officer)
Joined
Feb 13, 2016
Messages
44,595
Likes
239,613
Location
Seattle Area
What gives you the confidence that this piece of software can be trusted in any way?
I trust the company (Gibson Research). They have been around forever.

But yes, there is some risk and I was worried about installing the software.

Related, there are people who are distributing malware claiming to be a patch for these bugs. So be very careful.
 
Top Bottom